
CompTIASecurityX (CASP+)
Domain 4Objective 3
Threat Hunting CAS-005 Practice Questions (Page 8)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
15concepts
22%of the exam
Questions 36–40
- 36
A security analyst is tasked with proactively identifying potential threats to the organization's new cloud-based collaboration tool. The analyst wants to find publicly available information that could be used by an attacker to craft a targeted phishing campaign. Which OSINT technique would be MOST effective for this specific goal?
Select an answer first - 37
Why is the dark web considered a valuable source of threat intelligence?
Select an answer first - 38
A security operations center (SOC) uses a SIEM platform. An analyst has identified a new attack pattern that involves a specific sequence of PowerShell commands and a connection to a known malicious IP address. The analyst wants to create a detection mechanism that will alert the SOC whenever this pattern is observed in the SIEM's log data. Which approach is MOST appropriate?
Select an answer first - 39
A security team deploys a honeypot that appears to be an unpatched database server. What type of intelligence can the team most directly gain from this deployment?
Select an answer first - 40
What is the primary purpose of Snort rules?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.